Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2327
HistoryJul 22, 2022 - 12:00 a.m.

CVE-2022-2327

2022-07-2200:00:00
ubuntu.com
ubuntu.com
26
io_uring security vulnerability
kernel upgrade
double free.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.6%

io_uring use work_flags to determine which identity need to grab from the
calling process to make sure it is consistent with the calling process when
executing IORING_OP. Some operations are missing some types, which can lead
to incorrect reference counts which can then lead to a double free. We
recommend upgrading the kernel past commit
df3f3bb5059d20ef094d6b2f0256c4bf4127a859

Notes

Author Note
rodrigo-zaiden duplicate or much related to CVE-2022-2209
sbeattie initial investigation indicates that this likely only affects 5.10 and earlier, but not as far back as 5.4. But everything about this issue is unclear.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

15.6%